CVE-2025-11368
LearnPress – WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure
Record summary
CVE-2025-11368 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 31, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesBrowse thimpress / LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesDefault status: unaffected | CVE List | Through 4.2.9.4 | affected |
learnpressBrowse thimpress / learnpress | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMLearnPress < 4.3.0 - Arbitrary Callback Execution to Information ExposureCVSS 5.3
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.
Impact
Unauthenticated attackers can access sensitive admin curriculum, quiz answers, and course materials, compromising educational content confidentiality.
Remediation
Update to the latest version beyond 4.2.9.4.
Source: ProjectDiscovery